środa, 6 kwietnia 2022

Pentesting Pentesters with MSF Jump Host

Let's think about the scenario for a pentest/redteam project during which we are using 'our dedicated jump host'. "What if" someone will takeover this host? This time we'll try to check the potential results of this kind of attack. Here we go...

poniedziałek, 4 kwietnia 2022

Ansible - Quick Shot

I decided to create this small document to collect few basic ideas about Ansible and how it can be used during a ‘day-to-day’ scenarios for pentest and red team projects. If you’re already familiar with Ansible – this document more likely will be a small ‘cheat sheet’ if you’d like to use Ansible to perform some actions during the projects. Anyhow… Enjoy and have fun! ;) Here we go...

piątek, 1 kwietnia 2022

czwartek, 24 marca 2022

Another one SAST to bytes

During one of the last evenings I decided to read and learn more about static source code review. In the past I had a pleasure to create (more or less) 'automated' tools to do it. This time I decided to not to start "from the beginning" but instead of: to learn more about SAST and SonarQube scanning scenarios. Here we go...

niedziela, 20 lutego 2022

Space for XSS in Junos

"Space: the final frontier." Well... I'm not sure if it's even a half (of the journey) with Junos - but - let's find some "Space" to inject additional (JS/HTML) code. Get some "Space" and here we go...

poniedziałek, 14 lutego 2022

Enter in 2022

It was an interesting beginning of the year. After a few talks with few friends during last year, last few weeks I spent creating a new small tool called EnterTerminal. More details about it you'll find below. Here we go... 

piątek, 17 grudnia 2021

Quick intro to log4j

During this week I had a pleasure to learn more about a 'popular' log4j vulnerability. I decided to take a quick note for few cases I found in the IPS logs. Here we go...

piątek, 26 listopada 2021

Lore MIPS OOM

Few days ago I had a pleasure to present some of my ‘notes and ideas’ during TheHackSummit Conference. After (a “stage-fright” ate me alive and “ihmo - I failed”;)) the (“too fast!111”;)) presentation I decided to calm a bit and slow down with some binary exploitation topics. And that’s how I landed in the binary world of IoT and router devices… ;) Here we go…

piątek, 15 października 2021

Postauth Chained RCE with Nagios IM

Some time ago I started searching for bugs in NagiosIX. Few days ago I decided to continue my "research" and that's how I landed with NagiosIM (2.0.0 afaik ;)). Below you'll find few notes about it. :) Here we go...

czwartek, 14 października 2021

Pentesting Jenkins

Some time ago I started a small project called 'enlil'. As you already know - I'm using it during pentests and redteam projects. Below you'll find few notes about the test prepared for Jenkins. Here we go...